FAQ

Cybersecurity buying questions, answered clearly.

Practical answers for leaders evaluating risk, services, operating models and the right next step.

What does OyaCyber actually do?

We provide assessment, advisory, implementation, testing, monitoring, incident response and managed cybersecurity. Engagements can address a focused need or support the full security lifecycle.

How do I know which service my company needs?

You do not need to diagnose the answer alone. A first conversation or Security Assessment lets us understand the environment, objectives and material risks before recommending a project or managed service.

Do I need a penetration test or a vulnerability assessment?

A vulnerability assessment finds and prioritizes weaknesses broadly; a pentest uses controlled exploitation and manual analysis to validate attack paths and impact. Many programs use frequent assessments plus periodic, risk-based pentests.

How often should a company perform a penetration test?

Cadence depends on exposure, major releases, architecture changes, critical applications, customer commitments and regulation. Annual testing is a common baseline, not a universal answer.

What is MDR, and how is it different from a SOC?

A SOC is the people, processes and technology that operate detection and response. MDR is a managed service that delivers detection, investigation and coordinated response outcomes. A company can run its own SOC, outsource parts of it or use MDR.

Do I need a SOC if I already have security tools?

Tools produce telemetry and alerts; they do not automatically provide ownership, investigation, decisions or response. The operating capability must be designed around coverage, staffing, workflows and escalation.

Can OyaCyber work with our existing tools?

Yes. We assess the existing stack and operating model before recommending replacements. Our starting point is the client's risk and environment, not a predetermined product.

What happens during the first conversation?

We discuss business context, concerns, the current environment, incidents, customer or regulatory requirements, internal capabilities, priorities and timing. Then we identify whether an assessment, project or managed service is the sensible next step.

Do you work with internal security teams?

Yes. We can augment capacity, provide independent validation, add specialized capabilities or help the internal team build a roadmap and operating model.

Can OyaCyber act as our cybersecurity team?

Depending on need, Managed Cybersecurity, MDR and vCISO can combine operational coverage with strategic leadership. Business ownership remains with the client while responsibilities are clearly assigned.

What is a vCISO and when is one useful?

A vCISO provides fractional security leadership: strategy, risk priorities, governance, budgeting, executive communication and roadmap ownership. It is useful when those decisions need accountable leadership but a full-time CISO is not yet justified.

Can OyaCyber help with SOC 2, HIPAA, PCI DSS, NIST or ISO 27001?

We support readiness, gap analysis, control design, evidence practices and remediation. We do not present readiness work as an independent audit or promise certification.

Does compliance mean my company is secure?

No. Compliance and security overlap, but they are not the same. Compliance evaluates defined requirements at a point or period; security must also address changing threats, operating realities and risks outside the framework.

Can you assess Microsoft 365 and Azure?

Yes. Assessments can cover identity, privileged access, configuration, logging, data protection, workloads and governance within the agreed scope.

Can OyaCyber respond to an active incident?

Yes, subject to availability and a rapid scope confirmation. Incident Response focuses on containment, evidence, investigation, recovery coordination and clear executive communication. Use the urgent assistance CTA for an active event.

What information is needed to start?

It depends on the service. We lead discovery and identify the minimum useful evidence—such as scope, assets, architecture, stakeholders, constraints and objectives—without expecting the client to prepare a perfect package.

Do you work remotely and across which markets?

We support the United States, Brazil and Latin America through remote delivery and on-site work when appropriate to the engagement. OyaCyber operates across seven countries; individual countries are confirmed during scoping.

How large is the delivery capability?

OyaCyber is backed by 30+ years of enterprise technology experience, a broader group of 700+ professionals, 43 cybersecurity professionals and 35 cybersecurity specialties and capabilities. The 700+ figure represents the broader technology group, not only cybersecurity staff.

Why choose OyaCyber instead of a large vendor or boutique?

OyaCyber combines senior attention and a flexible specialist model with the operating experience and scale of an established technology group. We understand before prescribing and can connect advisory with execution across borders.

How are cybersecurity services priced?

Pricing reflects scope, environment, assets, users or endpoints, complexity, coverage, duration and response requirements. A focused discovery prevents false precision and produces a proposal tied to the work and outcome.

Do you offer recurring services, and can we start small?

Yes. MDR, SOC services, Managed Cybersecurity, vulnerability management, vCISO and continuous advisory are recurring options. Many relationships start with a focused assessment before a larger program.

You don't need to know which cybersecurity service to buy.

You need to understand your risk and determine what should happen next. That is where we start.

Talk to a Cybersecurity Expert